Executive brief
MB connect line's remote access platforms, used for industrial communication and machine maintenance, contain a security flaw. A user with low-level access can exploit this to view sensitive information across the entire database. This could lead to a total loss of confidentiality for customer data and system configurations.
Technical details
A SQL injection vulnerability exists in the getDevicegroups function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-level authenticated privileges can exploit this via the network to execute arbitrary SQL queries. Successful exploitation allows the attacker to read sensitive data from the database, resulting in a total loss of confidentiality.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory